Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Aug 2022AUTOBIZ, S.A. SUCURSAL EN ESPAÑAAUTOBIZ, S.A. Sucursal en España was fined by the AEPD €800 for sending unsolicited marketing messages. The authority also found that the company failed to provide a functional opt-out mechanism, breaching Article 21 of the LSSI.ESAEPDePrivacy€800
12 Jul 2022PUNTO ROJO LIBROS, S.LPUNTO ROJO LIBROS, S.L was fined EUR 800 by the AEPD for sending commercial emails without the recipient’s consent. The conduct breached Article 21 of the LSSI, which requires prior consent for this type of communication.ESAEPDePrivacy€800
27 Jul 2023B.B.B.B.B.B. was fined EUR 800 by the AEPD for installing a surveillance system that captured images and sounds from a neighbor’s property and potentially the public street. The authority found breaches of GDPR Articles 13 and 6(1), citing the lack of a valid legal basis and proper notice to affected individuals.ESAEPDGDPR€800
17 Dec 2024ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓNASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN was fined EUR 750 by the AEPD for failing to comply with a data protection authority resolution. The case concerns Article 58(2) of the GDPR.ESAEPDGDPR€750
26 Oct 2021ЧСИ2The Commission fined the private bailiff ЧСИ2 for unlawfully processing personal data by accessing bank account information after the enforcement proceeding had ended. The authority found a breach of the purpose limitation principle under Article 5 GDPR.BGCPDPGDPR€383
05 Jun 2023CHINA CENTER LLEIDACHINA CENTER LLEIDA was fined EUR 700 by the AEPD for failing to properly sign its video surveillance system and for not providing customers with required data protection information. The authority found a breach of Article 13 of the GDPR.ESAEPDGDPR€700
28 May 2026Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna TorrigianiThe Italian Data Protection Authority imposed a 700 EUR fine on Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna Torrigiani. The case concerned a data protection breach during a patient's hospitalization in the orthopedics department, including improper handling of information about HIV status.ITGaranteGDPR€700
07 Mar 2012INSTITUTO TECNOLOGICO AUTESEL SLINSTITUTO TECNOLOGICO AUTESEL SL was fined by the AEPD EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€600
14 Mar 2011IVY SOLUTIONS S.L.IVY SOLUTIONS S.L. was fined EUR 600 by the AEPD for sending unsolicited commercial emails without the recipient's consent. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€600
24 Feb 2011B.B.B.B.B.B. was fined EUR 600 by the AEPD for sending an unsolicited commercial email to the complainant without meeting the required legal conditions. The authority found a breach of Article 21 of the LSSI governing electronic commercial communications.ESAEPDePrivacy€600
26 Apr 2011VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined 600 EUR by the AEPD for sending unsolicited advertising SMS messages. The authority found that the messages were sent despite the recipient’s opt-out request, which breached Article 21.2 of the LSSI.ESAEPDePrivacy€600
27 Sept 2011EDICIONES FINDER, S.L.EDICIONES FINDER, S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails without recipient consent. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€600
01 Mar 2013QUARELY INDUSTRIAL S.L.QUARELY INDUSTRIAL S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which governs marketing communications without prior recipient consent.ESAEPDePrivacy€600
16 Jan 2026BAR GIOIA di XXThe Garante imposed a fine of EUR 600 on BAR GIOIA for the non-compliant installation of a video surveillance system. The case concerned breaches of data protection rules and the requirements for lawful processing.ITGaranteGDPR€600
01 Jan 2013CONSIGNALIA, S.L.CONSIGNALIA, S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited promotional emails. The authority found that this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€600
24 Mar 2010A.A.A.A.A.A. was fined EUR 600 by the AEPD for sending unsolicited commercial emails without recipient consent. The company also failed to provide information on how to exercise the right of cancellation, breaching Article 21 of the LSSI.ESAEPDePrivacy€600
31 Jan 2025SINDICAT CATAC-CTSCSINDICAT CATAC-CTSC was fined EUR 600 by the AEPD for failing to provide the required information. The authority found a breach of Article 58(1) of the GDPR.ESAEPDGDPR€600
14 Dec 2010EQUIPAMIENTO INTEGRAL DE OFICINAS S.L.EQUIPAMIENTO INTEGRAL DE OFICINAS S.L. was fined EUR 600 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits this type of communication without prior consent.ESAEPDePrivacy€600
11 May 2012PLEGADOS IRUÑA S.L.PLEGADOS IRUÑA S.L. was fined by the AEPD 600 EUR for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€600
31 Oct 2022TECNO MOTOR LA MUELA, S.L.L.TECNO MOTOR LA MUELA, S.L.L. was fined by the AEPD €600 for installing surveillance cameras oriented toward public areas without prior administrative authorization. The authority treated this as a breach of data protection rules.ESAEPDGDPR€600